CVE-2026-23246
published 2026-03-18CVE-2026-23246: In the Linux kernel, the following vulnerability has been resolved: wifi: mac80211: bounds-check link_id in ieee80211_ml_reconfiguration link_id is taken from…
PriorityP349high8.8CVSS 3.1
AVAACLPRNUINSUCHIHAH
EPSS
0.29%
21.1th percentile
In the Linux kernel, the following vulnerability has been resolved:
wifi: mac80211: bounds-check link_id in ieee80211_ml_reconfiguration
link_id is taken from the ML Reconfiguration element (control & 0x000f),
so it can be 0..15. link_removal_timeout[] has IEEE80211_MLD_MAX_NUM_LINKS
(15) elements, so index 15 is out-of-bounds. Skip subelements with
link_id >= IEEE80211_MLD_MAX_NUM_LINKS to avoid a stack out-of-bounds
write.
Affected
35 ranges· showing 25
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | linux | < linux 6.19.8-1 (forky) | linux 6.19.8-1 (forky) |
| linux | linux | — | — |
| linux | linux | >= 8eb8dd2ffbbb6b0b8843b66754ee9f129f1b2d6c < 650981e718e68005ca2760a6358134b8a98ebea4 | 650981e718e68005ca2760a6358134b8a98ebea4 |
| linux | linux | >= 8eb8dd2ffbbb6b0b8843b66754ee9f129f1b2d6c < bfde158d5d1322c0c2df398a8d1ccce04943be2e | bfde158d5d1322c0c2df398a8d1ccce04943be2e |
| linux | linux | >= 8eb8dd2ffbbb6b0b8843b66754ee9f129f1b2d6c < f35ceec54d48e227fa46f8f97fd100a77b8eab15 | f35ceec54d48e227fa46f8f97fd100a77b8eab15 |
| linux | linux | >= 8eb8dd2ffbbb6b0b8843b66754ee9f129f1b2d6c < d58d71c2167601762351962b9604808d3be94400 | d58d71c2167601762351962b9604808d3be94400 |
| linux | linux | >= 8eb8dd2ffbbb6b0b8843b66754ee9f129f1b2d6c < 162d331d833dc73a3e905a24c44dd33732af1fc5 | 162d331d833dc73a3e905a24c44dd33732af1fc5 |
| linux | linux_kernel | — | — |
| linux | linux_kernel | — | — |
| linux | linux_kernel | >= 0 < 6.19.8-1 | 6.19.8-1 |
| linux | linux_kernel | >= 6.13 < 6.18.17 | 6.18.17 |
| linux | linux_kernel | >= 6.13.0 < 6.18.17 | 6.18.17 |
| linux | linux_kernel | >= 6.19 < 6.19.7 | 6.19.7 |
| linux | linux_kernel | >= 6.19.0 < 6.19.7 | 6.19.7 |
| linux | linux_kernel | >= 6.5.0 < 6.6.130 | 6.6.130 |
| linux | linux_kernel | >= 6.5.1 < 6.6.130 | 6.6.130 |
| linux | linux_kernel | >= 6.7 < 6.12.77 | 6.12.77 |
| linux | linux_kernel | >= 6.7.0 < 6.12.77 | 6.12.77 |
| msrc | azl3_kernel_6.6.126.1-1_on_azure_linux_3.0 | — | — |
| ubuntu | linux | — | — |
| ubuntu | linux-fips | — | — |
| ubuntu | linux-gcp | — | — |
| ubuntu | linux-gcp-6.8 | — | — |
| ubuntu | linux-gcp-fips | — | — |
| ubuntu | linux-gke | — | — |
CVSS provenance
nvdv3.18.8HIGHCVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
osv8.8HIGH
vendor_debian8.8LOW
vendor_redhat8.8HIGH
vendor_msrc5.9MEDIUM
vendor_ubuntu2.0LOW
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Ubuntu
Linux kernel (Oracle) vulnerabilities
vendor_ubuntu·2026-07-23·CVSS 2.0
CVE-2026-46073 [LOW] Linux kernel (Oracle) vulnerabilities
Title: Linux kernel (Oracle) vulnerabilities
Summary: Several security issues were fixed in the Linux kernel.
It was discovered that some AMD processors did not properly clear data in
the floating point divider unit during speculative execution. A local
attacker could use this to expose sensitive information. (CVE-2025-54505)
It was discovered that some AMD Zen 2 processors did not properly isolate
shared resources in the operation cache. A local attacker could possibly
use this issue to corrupt instructions executed at a higher privilege
level, resulting in privilege escalation. (CVE-2025-54518)
It was discovered that some AMD Zen 5 processors supporting RDSEED
instruction did not properly handle entropy, potentially resulting in the
consumption of insufficiently random values. A loca
Ubuntu
Linux kernel (NVIDIA) vulnerabilities
vendor_ubuntu·2026-07-23·CVSS 2.0
CVE-2026-43129 [LOW] Linux kernel (NVIDIA) vulnerabilities
Title: Linux kernel (NVIDIA) vulnerabilities
Summary: Several security issues were fixed in the Linux kernel.
It was discovered that some AMD processors did not properly clear data in
the floating point divider unit during speculative execution. A local
attacker could use this to expose sensitive information. (CVE-2025-54505)
It was discovered that some AMD Zen 2 processors did not properly isolate
shared resources in the operation cache. A local attacker could possibly
use this issue to corrupt instructions executed at a higher privilege
level, resulting in privilege escalation. (CVE-2025-54518)
It was discovered that some AMD Zen 5 processors supporting RDSEED
instruction did not properly handle entropy, potentially resulting in the
consumption of insufficiently random values. A loca
Ubuntu
Linux kernel vulnerabilities
vendor_ubuntu·2026-07-23·CVSS 2.0
CVE-2026-46073 [LOW] Linux kernel vulnerabilities
Title: Linux kernel vulnerabilities
Summary: Several security issues were fixed in the Linux kernel.
It was discovered that some AMD processors did not properly clear data in
the floating point divider unit during speculative execution. A local
attacker could use this to expose sensitive information. (CVE-2025-54505)
It was discovered that some AMD Zen 2 processors did not properly isolate
shared resources in the operation cache. A local attacker could possibly
use this issue to corrupt instructions executed at a higher privilege
level, resulting in privilege escalation. (CVE-2025-54518)
It was discovered that some AMD Zen 5 processors supporting RDSEED
instruction did not properly handle entropy, potentially resulting in the
consumption of insufficiently random values. A local attacke
Ubuntu
Linux kernel (GCP FIPS) vulnerabilities
vendor_ubuntu·2026-07-21·CVSS 2.0
CVE-2026-46073 [LOW] Linux kernel (GCP FIPS) vulnerabilities
Title: Linux kernel (GCP FIPS) vulnerabilities
Summary: Several security issues were fixed in the Linux kernel.
It was discovered that some AMD processors did not properly clear data in
the floating point divider unit during speculative execution. A local
attacker could use this to expose sensitive information. (CVE-2025-54505)
It was discovered that some AMD Zen 2 processors did not properly isolate
shared resources in the operation cache. A local attacker could possibly
use this issue to corrupt instructions executed at a higher privilege
level, resulting in privilege escalation. (CVE-2025-54518)
It was discovered that some AMD Zen 5 processors supporting RDSEED
instruction did not properly handle entropy, potentially resulting in the
consumption of insufficiently random values. A lo
Ubuntu
Linux kernel vulnerabilities
vendor_ubuntu·2026-07-20·CVSS 2.0
CVE-2026-46073 [LOW] Linux kernel vulnerabilities
Title: Linux kernel vulnerabilities
Summary: Several security issues were fixed in the Linux kernel.
It was discovered that some AMD processors did not properly clear data in
the floating point divider unit during speculative execution. A local
attacker could use this to expose sensitive information. (CVE-2025-54505)
It was discovered that some AMD Zen 2 processors did not properly isolate
shared resources in the operation cache. A local attacker could possibly
use this issue to corrupt instructions executed at a higher privilege
level, resulting in privilege escalation. (CVE-2025-54518)
It was discovered that some AMD Zen 5 processors supporting RDSEED
instruction did not properly handle entropy, potentially resulting in the
consumption of insufficiently random values. A local attacke
Red Hat
kernel: Linux kernel: Denial of Service in mac80211 Wi-Fi due to out-of-bounds write
vendor_redhat·2026-03-18·CVSS 8.8
CVE-2026-23246 [HIGH] CWE-787 kernel: Linux kernel: Denial of Service in mac80211 Wi-Fi due to out-of-bounds write
kernel: Linux kernel: Denial of Service in mac80211 Wi-Fi due to out-of-bounds write
In the Linux kernel, the following vulnerability has been resolved:
wifi: mac80211: bounds-check link_id in ieee80211_ml_reconfiguration
link_id is taken from the ML Reconfiguration element (control & 0x000f),
so it can be 0..15. link_removal_timeout[] has IEEE80211_MLD_MAX_NUM_LINKS
(15) elements, so index 15 is out-of-bounds. Skip subelements with
link_id >= IEEE80211_MLD_MAX_NUM_LINKS to avoid a stack out-of-bounds
write.
A flaw was found in the Linux kernel's mac80211 Wi-Fi subsystem. This vulnerability occurs in the ieee80211_ml_reconfiguration function when processing a Multi-Link (ML) Reconfiguration element. An attacker can provide a crafted link_id value that is not properly bounds-checked, lead
Microsoft
wifi: mac80211: bounds-check link_id in ieee80211_ml_reconfiguration
vendor_msrc·2026-03-10·CVSS 5.9
CVE-2026-23246 [HIGH] wifi: mac80211: bounds-check link_id in ieee80211_ml_reconfiguration
wifi: mac80211: bounds-check link_id in ieee80211_ml_reconfiguration
Mariner: Mariner
Linux: Linux
Customer Action Required: Yes
Remediation: CBL-Mariner Releases
Reference: https://learn.microsoft.com/en-us/azure/azure-linux/tutorial-azure-linux-upgrade
Debian
CVE-2026-23246: linux - In the Linux kernel, the following vulnerability has been resolved: wifi: mac80...
vendor_debian·2026·CVSS 8.8
CVE-2026-23246 [HIGH] CVE-2026-23246: linux - In the Linux kernel, the following vulnerability has been resolved: wifi: mac80...
In the Linux kernel, the following vulnerability has been resolved: wifi: mac80211: bounds-check link_id in ieee80211_ml_reconfiguration link_id is taken from the ML Reconfiguration element (control & 0x000f), so it can be 0..15. link_removal_timeout[] has IEEE80211_MLD_MAX_NUM_LINKS (15) elements, so index 15 is out-of-bounds. Skip subelements with link_id >= IEEE80211_MLD_MAX_NUM_LINKS to avoid a stack out-of-bounds write.
Scope: local
bookworm: resolved
bullseye: resolved
forky: resolved (fixed in 6.19.8-1)
sid: resolved (fixed in 6.19.8-1)
trixie: open
VulDB
Linux Kernel up to 6.12.76/6.18.16/6.19.6/7.0-rc1 wifi ieee80211_ml_reconfiguration link_id out-of-bounds (EUVD-2026-12809 / Nessus ID 302910)
vuldb·2026-05-23·CVSS 8.8
CVE-2026-23246 [HIGH] Linux Kernel up to 6.12.76/6.18.16/6.19.6/7.0-rc1 wifi ieee80211_ml_reconfiguration link_id out-of-bounds (EUVD-2026-12809 / Nessus ID 302910)
A vulnerability described as critical has been identified in Linux Kernel up to 6.12.76/6.18.16/6.19.6/7.0-rc1. This affects the function ieee80211_ml_reconfiguration of the component wifi. Such manipulation of the argument link_id leads to out-of-bounds read.
This vulnerability is traded as CVE-2026-23246. Access to the local network is required for this attack to succeed. There is no exploit available.
Upgrading the affected component is recommended.
OSV
wifi: mac80211: bounds-check link_id in ieee80211_ml_reconfiguration
osv·2026-03-18·CVSS 8.8
CVE-2026-23246 [HIGH] wifi: mac80211: bounds-check link_id in ieee80211_ml_reconfiguration
wifi: mac80211: bounds-check link_id in ieee80211_ml_reconfiguration
In the Linux kernel, the following vulnerability has been resolved:
wifi: mac80211: bounds-check link_id in ieee80211_ml_reconfiguration
link_id is taken from the ML Reconfiguration element (control & 0x000f),
so it can be 0..15. link_removal_timeout[] has IEEE80211_MLD_MAX_NUM_LINKS
(15) elements, so index 15 is out-of-bounds. Skip subelements with
link_id >= IEEE80211_MLD_MAX_NUM_LINKS to avoid a stack out-of-bounds
write.
OSV
CVE-2026-23246: In the Linux kernel, the following vulnerability has been resolved: wifi: mac80211: bounds-check link_id in ieee80211_ml_reconfiguration link_id is ta
osv·2026-03-18·CVSS 8.8
CVE-2026-23246 [HIGH] CVE-2026-23246: In the Linux kernel, the following vulnerability has been resolved: wifi: mac80211: bounds-check link_id in ieee80211_ml_reconfiguration link_id is ta
In the Linux kernel, the following vulnerability has been resolved: wifi: mac80211: bounds-check link_id in ieee80211_ml_reconfiguration link_id is taken from the ML Reconfiguration element (control & 0x000f), so it can be 0..15. link_removal_timeout[] has IEEE80211_MLD_MAX_NUM_LINKS (15) elements, so index 15 is out-of-bounds. Skip subelements with link_id >= IEEE80211_MLD_MAX_NUM_LINKS to avoid a stack out-of-bounds write.
GHSA
GHSA-g43x-jrqr-j62r: In the Linux kernel, the following vulnerability has been resolved:
wifi: mac80211: bounds-check link_id in ieee80211_ml_reconfiguration
link_id is
ghsa_unreviewed·2026-03-18
CVE-2026-23246 [HIGH] GHSA-g43x-jrqr-j62r: In the Linux kernel, the following vulnerability has been resolved:
wifi: mac80211: bounds-check link_id in ieee80211_ml_reconfiguration
link_id is
In the Linux kernel, the following vulnerability has been resolved:
wifi: mac80211: bounds-check link_id in ieee80211_ml_reconfiguration
link_id is taken from the ML Reconfiguration element (control & 0x000f),
so it can be 0..15. link_removal_timeout[] has IEEE80211_MLD_MAX_NUM_LINKS
(15) elements, so index 15 is out-of-bounds. Skip subelements with
link_id >= IEEE80211_MLD_MAX_NUM_LINKS to avoid a stack out-of-bounds
write.
No detection rules found.
No public exploits indexed.
Wiz
CVE-2026-23246 Impact, Exploitability, and Mitigation Steps | Wiz
blogs_wiz·CVSS 8.8
CVE-2026-23246 [HIGH] CVE-2026-23246 Impact, Exploitability, and Mitigation Steps | Wiz
## CVE-2026-23246 :
Linux Kernel vulnerability analysis and mitigation
In the Linux kernel, the following vulnerability has been resolved:
wifi: mac80211: bounds-check link_id in ieee80211_ml_reconfiguration
link_id is taken from the ML Reconfiguration element (control & 0x000f),
so it can be 0..15. link_removal_timeout[] has IEEE80211_MLD_MAX_NUM_LINKS
(15) elements, so index 15 is out-of-bounds. Skip subelements with
link_id >= IEEE80211_MLD_MAX_NUM_LINKS to avoid a stack out-of-bounds
write.
Source : NVD
## 8.8
Score
Published March 18, 2026
Severity HIGH
CNA Score 8.8
Affected Technologies
Linux Kernel
CBL Mariner
Has Public Exploit No
Has CISA KEV Exploit No
CISA KEV Release Date N/A
CISA KEV Due Date N/A
Exploitation Probability Percentile (EPSS) 5.5
Exploitation
Bugzilla
CVE-2026-23246 kernel: Linux kernel: Denial of Service in mac80211 Wi-Fi due to out-of-bounds write
bugzilla·2026-03-18·CVSS 8.8
CVE-2026-23246 [HIGH] CVE-2026-23246 kernel: Linux kernel: Denial of Service in mac80211 Wi-Fi due to out-of-bounds write
CVE-2026-23246 kernel: Linux kernel: Denial of Service in mac80211 Wi-Fi due to out-of-bounds write
In the Linux kernel, the following vulnerability has been resolved:
wifi: mac80211: bounds-check link_id in ieee80211_ml_reconfiguration
link_id is taken from the ML Reconfiguration element (control & 0x000f),
so it can be 0..15. link_removal_timeout[] has IEEE80211_MLD_MAX_NUM_LINKS
(15) elements, so index 15 is out-of-bounds. Skip subelements with
link_id >= IEEE80211_MLD_MAX_NUM_LINKS to avoid a stack out-of-bounds
write.
Discussion:
Upstream advisory:
https://lore.kernel.org/linux-cve-announce/2026031817-CVE-2026-23246-d29e@gregkh/T
https://git.kernel.org/stable/c/162d331d833dc73a3e905a24c44dd33732af1fc5https://git.kernel.org/stable/c/650981e718e68005ca2760a6358134b8a98ebea4https://git.kernel.org/stable/c/bfde158d5d1322c0c2df398a8d1ccce04943be2ehttps://git.kernel.org/stable/c/d58d71c2167601762351962b9604808d3be94400https://git.kernel.org/stable/c/f35ceec54d48e227fa46f8f97fd100a77b8eab15
2026-03-18
Published